Legal
Security
AIHRI's public security statement for this website.
Scope
This statement covers the AIHRI public website. Any future operational systems will be governed by their own security documentation before use.
Secure communications
The website is served over encrypted connections. Enquiry submissions are validated on the server and protected by a bot-verification challenge and rate limiting before they are relayed to AIHRI mailboxes.
Please do not submit sensitive material
The public website must not be used to send patient information, health data, clinical records, confidential assessment evidence, proprietary algorithms or other sensitive organisational documentation. Attachments are not accepted through the website.
Reporting security issues
This page does not authorise active security testing, scanning, exploitation or attempts to gain unauthorised access to the website or its supporting infrastructure. It provides a route for reporting security issues observed during ordinary, lawful use of the website.
Suspected security issues observed in that way may be reported to security@aihri.org. Please provide a clear description of the issue and, where possible, the steps needed to reproduce it. Do not include personal data belonging to third parties, exploit payloads capable of causing harm, or details of active attacks against unrelated systems. Please do not carry out testing that could disrupt the service or affect other users.
AIHRI asks that researchers give a reasonable period for review and remediation before publishing details of any reported issue.
Response principles
AIHRI aims to acknowledge substantive security reports promptly, to keep reporters informed of progress on material issues and to remediate confirmed vulnerabilities on a risk-proportionate basis.